Truffle Security found that 543,699 unique credentials exposed in public GitHub code were still valid when tested on July 27–28, 2026. Its analysis linked those live secrets to 1,103,438 exposures across files and forks in The Stack v3, a 15.9 TB code dataset assembled from about 224 million public repositories. The credentials included API keys, access tokens, database connection strings, and cloud service-account credentials; the median duration of public exposure was 784 days, and one active AWS key had been committed in 2009.
GitHub push protection reduced exposure density by 53% for supported secret types, but it does not remediate historical commits and has incomplete coverage: 51.8% of active credentials used formats not blocked by default protection, while 36.8% were committed after push protection became the default for free users. Google Cloud service-account credentials, MongoDB connection strings, and Google API keys were among the largest groups of usable secrets. Because revocation is not mandatory after GitHub reports findings to providers, organizations should scan full Git histories, immediately revoke or rotate exposed credentials, investigate potential abuse, adopt short-lived secrets, and automate alert-to-revocation workflows; the exposures may also persist in downstream AI-training datasets after removal from source repositories.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Truffle Security tested credentials linked to 1,103,438 public exposures and found 543,699 unique credentials that still authenticated. The active set included Google Cloud service-account credentials, MongoDB connection strings, and Google API keys, showing that exposed secrets can remain usable for years and persist in downstream training data.
The Stack v3 dataset crawl ended after collecting code from 224,553,295 public GitHub repositories. The 15.9 TB dataset was used for code-focused AI-model training and later credential-persistence analysis.
GitHub began enabling push protection by default for free users. The feature blocks recognizable secrets before publication, although developers can remove or bypass warnings and it does not remediate older commits.
GitHub made secret-scanning alerts available at no cost for public repositories, enabling detection of historical credential exposures for repository owners.
A database credential later found to remain valid was in an Erlang server configuration file last modified in June 2009. The credential was still usable when researchers tested it in 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcesecurityweek.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.